Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / OpenBao

In Oracle review

DCA Hardened Secrets Manager for OpenBao — Support & Quick Start

A hardened, CVE-patched virtual machine image running OpenBao — the Linux Foundation's open-source secrets-management engine — on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version2.5.5
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8200/tcp
CategorySecurity
Upstream licenceMPL-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@PUBLIC_IP
  2. OpenBao runs as a systemd service bound to 127.0.0.1:8200 only, TLS-terminated with a certificate generated uniquely for this instance at first boot. Check status:
    sudo systemctl status openbao
  3. The image ships uninitialized: no root token or unseal keys exist until you mint them. Initialize once, then unseal with 3 of the 5 keys it prints:
    export BAO_ADDR=https://127.0.0.1:8200
    export BAO_SKIP_VERIFY=true   # only until you install a certificate your clients trust
    bao operator init
    bao operator unseal   # run it three times, one key each; bao status then reports Sealed false
  4. Smoke-test with the Initial Root Token that init printed (store it and the unseal keys off the instance; they are shown once and cannot be recovered):
    export BAO_TOKEN=INITIAL_ROOT_TOKEN
    bao secrets enable -path=secret kv-v2
    bao kv put -mount=secret smoke hello=world
    bao kv get -field=hello -mount=secret smoke
  5. To reach OpenBao from your application tier, expose it deliberately: install a certificate your clients trust as /etc/openbao/tls/tls.crt and /etc/openbao/tls/tls.key (owner openbao, key mode 0600), then bind the listener to all interfaces and restart:
    sudo sed -i 's/"127.0.0.1:8200"/"0.0.0.0:8200"/' /etc/openbao/bao.hcl
    sudo systemctl restart openbao   # OpenBao restarts sealed: unseal again as in step 3

    Port 8200 is already permitted in the host firewall. Restrict it in your VCN security list to the application tier's CIDR; never expose a secrets store to the internet. The cluster port (8201) remains blocked by the host firewall.

  6. Data (Raft integrated storage) lives in /var/lib/openbao; for production, back it with a block volume. The first-boot TLS material lives in /etc/openbao/tls/.

The image is CVE-patched at build time. OpenBao itself comes from the upstream release RPM (upgrade it by installing a newer openbao_VERSION_linux_amd64.rpm from github.com/openbao/openbao/releases); apply OS updates with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

OpenBao is a trademark of the Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the OpenBao project or the Linux Foundation.